import test from 'node:test'; import assert from 'node:assert/strict'; import fs from 'node:fs/promises'; import os from 'node:os'; import path from 'node:path'; import crypto from 'node:crypto'; import {spawnSync} from 'node:child_process'; test('supervised SDK reads a credential file and proves instance identity without an environment token', async t => { const directory = await fs.mkdtemp(path.join(os.tmpdir(), 'qx-sdk-credential-')); t.after(() => fs.rm(directory, {recursive:true, force:true})); const token = crypto.randomBytes(32).toString('hex'); const filename = path.join(directory, 'process-token'); await fs.writeFile(filename, token, {mode:0o600}); const env = {...process.env, CAMINO_RUNTIME_AUTH_TOKEN_FILE: filename, CAMINO_RUNTIME_AUTH_REQUIRED:'1', QUIXOS_RUNTIME_INSTANCE_ID:'instance:test'}; delete env.CAMINO_RUNTIME_AUTH_TOKEN; const result = spawnSync(process.execPath, ['--input-type=module', '-e', ` import {createPackageRuntimeRoutes} from ${JSON.stringify(new URL('../dist/index.js', import.meta.url).href)}; createPackageRuntimeRoutes({packageRevisionId:'package:test',exports:{}})({ service(_type, implementation) { console.log(JSON.stringify(implementation.handshake({nonce:'challenge'}))); } }); `], {env, encoding:'utf8'}); assert.equal(result.status, 0, result.stderr); const handshake = JSON.parse(result.stdout); assert.equal(handshake.authenticationProof, crypto.createHmac('sha256', token) .update(JSON.stringify(['challenge','instance:test','package:test'])).digest('hex')); assert.ok(handshake.capabilities.includes('epoch-grants-v1')); assert.ok(!result.stdout.includes(token)); });